|7 min read|Yvann Lièvre

AI Act and Cybersecurity: What It Changes for Detection Tools

Risk classification, transparency obligations, and AI detection tool compliance. How ThreatClaw stays ahead of the AI Act.

AI ActIA

The European AI Act has been progressively taking effect since February 2025. For cybersecurity vendors using AI (intrusion detection, behavioral analysis, automated threat intelligence) the implications are concrete and immediate.

Risk Classification Applied to Cybersecurity

The AI Act classifies AI systems into four risk levels. For cybersecurity tools, classification depends on the usage context:

Minimal Risk

Log analysis tools, signature-based malware detection, or traditional vulnerability scanners are generally not subject to specific AI Act obligations, as their AI component is marginal.

Limited Risk

Security chatbots, automated report generation tools, and LLM-based alert classification systems are subject to transparency obligations: users must know they are interacting with AI.

High Risk

This is where things get complex. AI systems used for critical infrastructure security may be classified as high risk, which requires:

  • A documented quality management system

  • Traced and quality training data

  • Complete technical documentation

  • Systematic human oversight

  • Robustness and accuracy testing

  • Logging of AI decisions

What Concretely Changes for SOC Teams

For security teams using AI-based detection tools, the AI Act mandates:

  • Alert explainability: a SOC analyst must understand why the AI raised an alert. Pure black-box models are no longer sufficient

  • Decision traceability: every automated decision (IP blocking, machine isolation, file deletion) must be logged with associated reasoning

  • Human oversight: critical actions must maintain a human-in-the-loop

  • Bias and false positives: vendors must document false positive rates and potential biases of their models

ThreatClaw: AI Act Compliance by Design

At ThreatClaw, we anticipated these requirements from the design of our security platform:

  • Algorithmic transparency: every alert includes model reasoning, indicators used, and confidence score

  • Complete logging: all AI decisions are traced with timestamp, context, and justification

  • Configurable human-in-the-loop: automatic action thresholds are customizable, with mandatory human validation above a criticality level

  • Complete technical documentation available for compliance audits

Pitfalls to Avoid

  • Ignoring classification: failing to assess the risk level of your AI tools is the first mistake. Start with an inventory

  • Confusing GDPR and AI Act compliance: the AI Act adds AI-specific requirements beyond data protection

  • Forgetting third-party providers: if you use a third-party AI model in your detection pipeline, you are a "deployer" under the AI Act with your own obligations

Discover how our experts can help align your detection tools with the AI Act. Check out our plans.

FAQ

Are SIEM tools covered by the AI Act?

A traditional rule-based SIEM generally is not. However, a SIEM integrating ML or LLM detection modules falls within the AI Act's scope.

Who is responsible: the vendor or the user?

Both. The vendor ("provider") must ensure the system's compliance. The user organization ("deployer") must use it according to instructions and maintain human oversight.

Does the AI Act apply to open-source models?

General-purpose open-source models benefit from exemptions, unless they present systemic risk (models trained with more than 10^25 FLOPS). An open-source model integrated into a commercial product is subject to the product's obligations.

What is the AI Act timeline?

Bans on unacceptable risk practices have applied since February 2025. Obligations for high-risk systems fully apply from August 2026.

Related articles